Server-Side Request Forgery Vulnerability in Camaleon CMS by Owen2345
CVE-2026-86100
5.3MEDIUM
What is CVE-2026-86100?
Camaleon CMS versions 2.7.5 through 2.9.1 lack proper validation of redirect targets in the Upload from URL feature. This oversight allows authenticated attackers to inject malicious URLs, bypassing initial validation. While fetching remote files, these URLs can redirect to internal network services, potentially exposing sensitive data and system internals to unauthorized access. It emphasizes the need for enhanced validation and security measures in file upload mechanisms to mitigate such risks.
Affected Version(s)
CamaleonCMS 2.7.5 < 2.9.2
